Your information

Privacy Notice

How St. Mary’s Cathedral Aberdeen collects, uses, stores and protects personal information, and the rights available to you under UK data protection law.

Last updated 20 August 2026

Who we are

St. Mary’s Cathedral Aberdeen, the Church of Saint Mary Assumed into Heaven, is responsible for the personal information described in this notice where it acts as the data controller.

Contact details

St. Mary’s Cathedral Aberdeen
Huntly Street
Aberdeen AB10 1SH
Scotland, United Kingdom

For privacy or data protection enquiries, please use ourcontact pageor write to us at the postal address above.

Information we use

Personal data we may collect

Depending on how you interact with the Cathedral, we may collect information such as your name, postal address, email address, telephone number, enquiry details, event or ministry information, donation information, communication preferences, and technical information generated when you use the website.

Some pastoral, sacramental or ministry activities may involve information revealing religious belief or other special category data. Where we need to process this type of information, we will do so only where an appropriate condition under data protection law applies and with additional care appropriate to its sensitivity.

We normally receive information directly from you. In limited circumstances we may receive information from a parent or guardian, another parish or church body, a service provider acting on your behalf, or another source where there is a lawful reason to do so.

Purpose & lawful basis

Why we use personal information

Enquiries & parish administration

To respond to messages, arrange visits, administer parish activities and provide information you request. We generally rely on legitimate interests, steps taken at your request before entering an arrangement, or another lawful basis appropriate to the circumstances.

Sacraments & pastoral activity

To administer sacramental preparation, pastoral care and related church records. The lawful basis and any special-category condition will depend on the activity and applicable church and legal requirements.

Donations & financial records

To process donations, maintain financial records, administer Gift Aid where applicable, prevent fraud and meet accounting, tax or other legal obligations.

Volunteering, ministries & events

To organise participation, communicate practical information, manage safeguarding where relevant and operate Cathedral events and ministries.

Communications

To send requested or appropriate parish communications. Where consent is required for electronic marketing or similar communications, we will seek it and you may withdraw it at any time.

Website operation & security

To provide, maintain and secure the website, diagnose faults, protect against misuse and understand how services are functioning. We use consent where the law requires it for non-essential cookies or similar technologies.

Sharing & suppliers

Who may receive your information

We may share personal information where necessary with authorised Cathedral or diocesan personnel, professional advisers, payment and donation providers, website and hosting providers, form or email service providers, event service providers, safeguarding bodies, public authorities, regulators or law-enforcement bodies where required or permitted by law.

Our planned WordPress website may use services such as The Events Calendar, GiveWP and Fluent Forms. If those services are enabled, their providers or connected payment, email and hosting services may process personal information on our behalf or, in some circumstances, as separate controllers. We will configure such services in accordance with applicable data protection requirements and update this notice if material processing arrangements change.

We do not sell your personal information.

International transfers

Where information is processed

Some technology or service providers may process information outside the United Kingdom. Where a restricted international transfer takes place, we will use an appropriate legal transfer mechanism and safeguards required by UK data protection law.

Retention

How long we keep information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, and for any additional period required by law, safeguarding obligations, financial or audit requirements, dispute resolution, or legitimate church record-keeping needs.

Retention periods therefore vary by record type. For example, routine enquiries are normally kept only while they remain useful for dealing with the matter, while financial, sacramental or safeguarding records may need to be retained for substantially longer periods. We periodically review information and securely delete or anonymise it when it is no longer required.

Cookies & external content

Website technologies

This website may use strictly necessary technologies required for security, accessibility or core site operation. Where optional analytics, advertising, embedded media or other non-essential cookies or similar technologies are introduced, we will provide appropriate information and request consent where required before they are used.

Pages may contain links to external websites or services. Those organisations are responsible for their own privacy practices, and we encourage you to read their privacy information before providing personal data.

Your choices

Your data protection rights

Depending on the circumstances and the lawful basis being used, you may have rights to be informed about our processing, access your personal information, correct inaccurate information, request erasure, restrict processing, receive portable information, or object to certain processing. You may also have rights in relation to solely automated decision-making.

Your right to object

You have the right to object to processing based on legitimate interests in certain circumstances. You also have an absolute right to object to the use of your personal information for direct marketing.

If we rely on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

To exercise a right, please contact us using the details above. We may need to verify your identity before acting on a request. Rights are not absolute and exemptions may apply in some circumstances.

Complaints

How to raise a concern

Please contact us first if you have a concern about how we use your personal information so that we can try to resolve it.

You also have the right to complain to the UK supervisory authority, the Information Commissioner’s Office (ICO). Information about making a complaint is available atico.org.uk/make-a-complaint/.

Security & updates

Protecting information and changes to this notice

We use proportionate organisational and technical measures designed to protect personal information against accidental or unlawful loss, alteration, disclosure or access. Access is limited to people who need the information for legitimate Cathedral or service purposes.

We may update this notice when our website, services or legal obligations change. The latest version will be published on this page with a revised “last updated” date.

Scroll to Top